Skip to content
Ad Plus - Agencja Widoczności w AI

Cookie policy

How cookies are used on the adplus.pl website.

COOKIE POLICY

Ad Plus Polska Sp. z o.o.

This is a translation of the Polish document available at adplus.pl/polityka-cookies. In case of any discrepancy between the language versions, the Polish version prevails.

Under which laws are or may your personal data be processed?

The rules on the protection of personal data are set out, among others, in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter GDPR), in the Polish Personal Data Protection Act of 10 May 2018, and in special acts (lex specialis) under national law.

Key definitions

  • "Personal data" - means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person,
  • "Cookies" - a cookie is a small text file that a website saves on a user's computer or mobile device when the website is viewed,
  • "Website" - the service provided at https://adplus.pl,
  • "Processing" - means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction,
  • "Controller" - or data controller - means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law,
  • "Joint controller" - joint controllership occurs when at least two controllers jointly determine the purposes and means of processing,
  • "Third party" - means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data,
  • "Supervisory authority" - means an independent public authority established by a Member State,
  • "Consent" - consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her,
  • "Profiling" - means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements,
  • "Cookie Policy" - information on the use of cookies on the website operated by the controller. The cookie policy is available on the controller's website. Cookies may belong to the controller or to third parties,
  • "GDPR" - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
  • Who does this Cookie Policy apply to? This Cookie Policy applies to users of the website whose personal data are processed using cookies used on the website or its subpages.

Who is the controller of personal data?

The controller of personal data is Ad Plus Polska Spółka z ograniczoną odpowiedzialnością, with its registered office in Pęcław (05-530 Góra Kalwaria), Pęcław 57A, Poland, KRS 0001227688, NIP 1231599629, REGON 544183686.

Contact details of the controller

Contact details of the controller: Ad Plus Polska Sp. z o.o., Pęcław 57A, 05-530 Góra Kalwaria, Poland, kontakt@adplus.pl, tel.: +48 22 290 03 38.

Data Protection Officer

The controller has not appointed a Data Protection Officer. Enquiries regarding the protection of personal data should be addressed directly to the controller's postal address or to the dedicated e-mail address: kontakt@adplus.pl.

Who is the supervisory authority?

  • The supervisory authority is the President of the Personal Data Protection Office (Poland).

Which cookies are used?

  • The following types of cookies are or may be used on the website and its subpages:
  • storing the preferences of the website visitor,
  • ensuring the operation and technical aspects of the website,
  • collecting analytical data (on user behaviour, profiling),
  • third-party cookies,
  • cookies of other websites. Analytical, profiling and tracking cookies belonging to third parties

For the cookies listed below, the legal basis for processing personal data is Article 6(1)(a) GDPR - the consent of the data subject. Giving consent is voluntary, and withholding it means that the cookies will not be used for the purposes for which they were intended:

  • No.
  • Name
  • Category
  • Type
  • Scope of data
  • Purpose of use
  • Duration
  • Legal basis
  • _ga
  • Analytical
  • Operational / analytical
  • User identifier, information on visits, activity, device and browser
  • Traffic analysis and Google Analytics 4 statistics
  • Up to 2 years
  • Consent - Article 6(1)(a) GDPR,
  • _ga_G-X41HKP8YYP
  • Analytical
  • Operational / analytical
  • Session and user activity data
  • Maintaining session state and measuring activity in GA4
  • Up to 2 years
  • Consent - Article 6(1)(a) GDPR,
  • Google Analytics 4
  • Analytical
  • Third-party script
  • Cookie data, IP address (within the GA4 configuration), device data, user behaviour, entry source
  • Statistics, analysis of website use, service optimisation
  • Up to 14 months
  • Consent - Article 6(1)(a) GDPR,
  • Meta Pixel (_fbp)
  • Marketing
  • Tracking / profiling, third-party script
  • Browser identifier, information on visited pages, events, conversions, interactions with ads
  • Remarketing, measuring ad effectiveness, building audiences, personalising Meta ads
  • Up to 3 months
  • Consent - Article 6(1)(a) GDPR,
  • FastTony (pixel.fasttony.com)
  • Marketing
  • Third-party script
  • Data on page views, conversions, marketing identifiers, campaign data (depending on configuration)
  • Managing marketing pixels and advertising campaigns
  • Depends on configuration
  • Consent - Article 6(1)(a) GDPR, Operational and technical cookies used by the controller

For the cookies listed below, the legal basis for processing personal data is Article 6(1)(f) GDPR - the legitimate interest pursued by the controller. The legitimate interest of the controller is understood as the activities described below:

  • No.
  • Name
  • Category
  • Type
  • Scope of data
  • Purpose of use
  • Duration
  • Legal basis
  • laravel_session
  • Necessary
  • Technical
  • Session identifier, data necessary to maintain the session
  • Ensuring the operation of the website, maintaining the user session
  • Until the end of the session or approx. 120 minutes
  • Article 6(1)(f) GDPR
  • XSRF-TOKEN / CSRF Token
  • Necessary
  • Technical / security
  • Token protecting against CSRF attacks
  • Protection of forms and website security
  • Approximately 120 minutes
  • Article 6(1)(f) GDPR
  • Google reCAPTCHA (_GRECAPTCHA and other Google cookies)
  • Functional / security
  • Third-party script
  • Data on the device, browser, IP address, user behaviour
  • Protection of forms against bots and spam
  • Depends on Google's configuration
  • Article 6(1)(f) GDPR
  • cookie-notice-dismissed (localStorage)
  • Necessary
  • Technical / functional
  • Information that the cookie notice has been closed
  • Remembering the user's preference regarding the cookie notice
  • Until the user clears the site data
  • Article 6(1)(f) GDPR

Cookies of other websites

On some pages or subpages belonging to the controller, cookies of other websites may be used, and content from external entities such as YouTube, Facebook or Google Maps may be displayed. To view content from external entities, the user must first accept their detailed terms. Part of those terms is a cookie policy over which the controller has no control, and the controller is not responsible for the processing of personal data collected through the cookies of those websites:

How to manage cookies?

Cookies can be managed and deleted freely. Your browser or device may offer settings that allow you to choose whether browser cookies are set, and also to delete them. These settings differ between browsers, and manufacturers may change both the settings they make available and the way they work at any time. Additional information on the settings offered by individual browsers can be found at the links below:

List of entities that may transfer personal data outside the EEA and that may not provide sufficient protection of personal data as required by the GDPR:

No.

Name of the entity

Link to information

Possible negative consequences for the data subject

Facebook

https://www.facebook.com/legal/terms

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

YouTube

https://www.youtube.com/t/terms

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

Google

https://policies.google.com/terms?hl=en&gl=be

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

Google Maps

https://www.google.com/intl/en_be/help/terms_maps/

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

Disclosure of personal data

Personal data are disclosed to data recipients. The categories of recipients are entities providing marketing services, advertising agencies and marketing agencies with which the controller has concluded a processing agreement under Article 28 GDPR. A list of the entities to which personal data are entrusted is available at the request of the data subject.

Exercising the rights of data subjects

You have the right to request that the controller give effect to the following rights:

  • the right of access to the personal data concerning the data subject,
  • the right to rectification of personal data,
  • the right to erasure of personal data,
  • the right to restriction of processing of personal data,
  • the right to object to processing,
  • the right to data portability,
  • the right to receive a copy of one's personal data,
  • the right to lodge a complaint with the supervisory authority (https://uodo.gov.pl/pl/83/155). Under Article 77 GDPR you may lodge that complaint either with the controller's authority in Poland or with the authority of the EU or EEA Member State where you live, work, or where the alleged infringement took place.
  • Owing to the individual purposes of processing referred to in this Cookie Policy, the exercise of data subjects' rights may be limited in whole or in part, for example because of applicable laws which oblige the controller to process the data. Data protection impact assessment (DPIA)

Where a type of processing - in particular using new technologies - is likely to result in a high risk to the rights and freedoms of natural persons by reason of its nature, scope, context and purposes, the controller carries out, prior to the processing, an assessment of the impact of the envisaged processing operations on the protection of personal data,

In connection with the use of profiling and third-party cookies on the website, personal data processed through those cookies may be transferred to a third country, i.e. outside the EEA. Where personal data are transferred outside the European Economic Area, the country in question may not ensure sufficient protection of personal data, may not ensure that the rights granted under the GDPR can be exercised, and a personal data breach may occur. The transfer of personal data outside the EEA may involve a high risk that sufficient security of the processed personal data is not ensured,

List of entities that may transfer personal data outside the EEA and that may not provide sufficient protection of personal data as required by the GDPR:

No.

Name of the entity

Link to information

Possible negative consequences for the data subject - high risk

Facebook

https://www.facebook.com/legal/terms

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

YouTube

https://www.youtube.com/t/terms

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

Google

https://policies.google.com/terms?hl=en&gl=be

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage

Google Maps

https://www.google.com/intl/en_be/help/terms_maps/

  1. unauthorised access to data,

  2. loss of control over one's data,

  3. inability to exercise the rights granted under the GDPR,

  4. other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage